← Back to CVE Index
CVE-2025-61106
Disclosed 2025-10-27
Description
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
Severity & CVSS Score
7.5
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-476 | NULL Pointer Dereference |
Affected FRR Versions
- < 10.6.0
Versions prior to 10.0 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/19983 | GitHub |
Git Fixes
Raw Data
- CVE-2025-61106.cve.json — CVE record (JSON)
- CVE-2025-61106.frr.json — FRR-specific data (JSON)